We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 21969
    • 4 Posts
    Has anyone encountered any security problems using the base href tag?

    I implemented FURLs the other day. In the process I added <base href="[(site_url)]" /> to my template headers. Had FURLs working perfectly. The next morning though I discovered that the site had been hacked and whoever got in has somehow changed the base href tag so that the URLs now point to someone completely different.

    Anyone else experience this?

    Basically, I’m trying to track down if it is a security issues with MODx and the base href tag OR (I’m leaning toward this one) if someone truly hacked into the server and made changes.

    Any insight is much appreciated.
    • Please don’t double post.
        Ryan Thrash, MODX Co-Founder
        Follow me on Twitter at @rthrash or catch my occasional unofficial thoughts at thrash.me

      This discussion is closed to further replies. Keep calm and carry on.